[DNSOP] Re: PQ DNSSEC?
Peter Thomassen <[email protected]> Tue, 21 Jul 2026 15:28:01 +0200
| Newsgroups | gmane.ietf.dnsop |
|---|---|
| Message-ID | <[email protected]> |
Hi Philip, On 7/21/26 14:41, Philip Homburg wrote: > I wonder, is it time that somebody signs a zone with ML-DSA-44 and then > uses RIPE Atlas to see what breaks? We (deSEC in collaboration with SandboxAQ) have done this two years ago when it was still Dilithium2, results at the bottom of our test bed page at https://pq-dnssec.dedyn.io/. For Dilithium2, we used algorithm number 18. Our BIND setup has separate KSK and ZSK keys, and pdns setup uses just one CSK. We found failure rates between 10% and 40% (slide numbers from [1]): Query for an existing record: - Slide 6: BIND auth, UDP failure rate 29-33%, TCP failure rate 21-22% - Slide 7: pdns auth, UDP failure rate 10-11%, TCP failure rate ~7% Variation is from whether the query had the DO bit set or not (and the usual noise). Query for a non-existing name: - Slide 8: BIND auth, UDP failure rate 36-43%, TCP failure rate 35-46% - Slide 9: pdns auth, UDP failure rate 29-31%, TCP failure rate 20-29% Additional variation here depending on NSEC vs. NSEC3. Note that the numbers are from 2024; it may be worthwhile repeating this to get a picture that is both current and uses an implementation that follows the actual ML-DSA-44 spec. Best, Peter [1]: https://datatracker.ietf.org/meeting/120/materials/slides-120-maprg-field-experiments-on-post-quantum-dnssec-01.pdf _______________________________________________ DNSOP mailing list -- [email protected] To unsubscribe send an email to [email protected]